← Back to Job Holster
Privacy Policy
Last updated: September 6, 2026
Job Holster ("Job Holster," "we," "us," "our") is operated by Jobholster LLC, a company registered in Missouri, United States. This policy explains, in plain language, what data the Job Holster mobile and web app ("the app") collects, why we collect it, who we share it with, and the choices you have. Questions? Email [email protected].
The short version
- We collect your account email, the client and job information you enter, basic usage analytics, crash reports, and your subscription status.
- Your account data is stored with access controls. Teammates you invite can access shared workspace records according to their role.
- We do not sell your data, we do not use it for advertising, and we do not track you across other apps or websites.
- You can delete your account from inside the app after completing any required workspace ownership steps.
Who the data belongs to
Job Holster is a tool for tradespeople to track their own jobs and clients. Much of what you enter (your clients' names, phone numbers, addresses, photos, and notes) is personal information about other people. You are responsible for having a lawful basis to store that information; you act as its controller, and we process it on your behalf to provide the app.
What we collect and why
- Account information. Your email address and authentication credentials, handled by our authentication provider, to create and secure your account. If you sign in with Apple or Google, we receive a unique identifier and your email address from them. Nothing else.
- Content you create. Client and job records: names, phone numbers, addresses, custom fields, tags, field-change history, pasted messages, notes, voice-memo audio, AI-cleaned transcripts, photos, and drawings. This is stored to provide the app's core function, share records with invited teammates, and sync across your devices.
- Usage analytics. We use a product-analytics service to understand which features are used so we can improve the app. These events are tied to a random account identifier (a UUID), not your email, name, or client content. Autocapture and session recording are turned off. You can opt out any time in Settings → Setup & advanced → Privacy. On the public website, we also count which App Store or Google Play button was tapped and where that button appeared. This aggregate click count does not use a cookie, create a visitor profile, or tell us whether an app was installed.
- Crash diagnostics. We use a crash-reporting service to receive crash reports (error details, device model, OS version) so we can fix bugs. Crash reports do not include your client content.
- Photo location (optional). If photo location tagging is on, the app reads your device location when you add a photo so it can stamp that photo with where the work happened. The coordinates are turned into a place name by our reverse-geocoding provider, BigDataCloud, and kept with that photo on your own jobs. Location is used only for this. There is no background or continuous location, and it is never used for tracking or advertising. You can turn photo tagging off in Settings under Business & branding, or deny the location permission, and still use every other part of the app.
- Subscription information. If you subscribe, our subscription-management provider, together with Apple or Google, processes the purchase and tells us your subscription status so we can unlock paid features. We never receive your full payment-card details.
- AI features. When you use "Analyze with AI" or "Format with AI," the text or screenshot you choose to analyze and, for matching, the names, phone numbers, and addresses of existing customers in your workspace are sent through our proxy to Anthropic (Claude). When you use "Proofread," only the text you are proofreading is sent to Anthropic, and no customer details are sent for matching. In the iPhone and Android apps, voice-memo audio you choose to transcribe is sent to Cloudflare Workers AI, which runs the Whisper speech-recognition model on Cloudflare's infrastructure. On a supported web browser, live voice transcription may send microphone audio to that browser vendor's speech service. These actions happen only after you agree to the in-app AI notice. Photos attached to jobs, your password, and customer fields beyond the listed matching details are not sent to Anthropic. Core job tracking works without AI.
- Job request forms. A business using Job Holster can share a link or a QR code that opens a request form. If you are a homeowner or a customer filling one of those in, you are not a Job Holster user and you do not need an account. What you send is your name and phone number, and optionally your email address, the job address, a description of the work, and photos. It goes to the one business whose link you used, so they can get back to you about that job. It is never sent to any other business, never pooled with anyone else's, never sold, and never used to advertise to you. We email that business to let them know a request came in; that email contains only your first name and their business name, and nothing else you wrote. After that, the business decides what to do with your details, the same as if you had texted the details to them yourself, and they are responsible for them. See Data retention below for how long a request sticks around, and Your rights and choices if you want yours removed.
- Approving an estimate. A business using Job Holster can text you a private link to an estimate or quote. If you are a homeowner or a customer opening one of those, you are not a Job Holster user and you do not need an account. You can read it and do nothing. If you choose to approve it, we record the name you type, the date and time, which version of the document you were looking at, which optional items you ticked, and, if you draw one, your signature. We also record the IP address and browser user-agent of the device you approved from. Those last two are not there to profile you: an approval is the record of an agreement about money, and the business needs to be able to show when and from where it was given if it is ever questioned. If you decline or ask for a change instead, we record that and any message you type. All of it goes to the one business whose link you used and becomes part of their record of that job. It is never sent to any other business, never sold, and never used to advertise to you. See Data retention below, and Your rights and choices if you want yours removed.
- Job requests read by AI. If a business has AI turned on in their workspace, a job request that comes in through their form is also read by Anthropic (Claude) as soon as it arrives, so their tags and job details can be filled in ready for them to review. What is sent is the description the customer typed, the names of the tags that business already uses, and the names and choices of their own job fields. The customer's name, phone number, email address, job address and photos are not sent for this. It does not run at all when AI is turned off for that workspace, and the same Anthropic terms below apply.
- Estimate and invoice payments. A business can turn on online payments and share a link so a customer can pay a deposit on an estimate or pay an invoice from their phone or computer. That payment page is served by us, but the actual payment (their card number or bank details) is entered directly into our payment processor, Stripe, and never passes through our servers or reaches the business. What we do store, tied to that one invoice or estimate record, is the amount, the payment's status (e.g. paid, refunded, disputed), the payment method type (card or bank), and the card's last four digits, so the business can see what happened without ever seeing the card itself. If the customer types their name on the pay page, it is shown back to the business on that record, the same as a name they might have written on a check. Stripe's own privacy policy governs what it does with the payment details it collects directly; we receive from Stripe only the status and summary information above. This feature is off by default and only applies to workspaces that have turned it on.
Who we share data with
We share data only with service providers ("processors") who handle it on our behalf under contract, solely to run the app:
| Provider | What they handle |
| Supabase | Cloud database, authentication, sign-in, and synced workspace storage |
| Cloudflare | App hosting / CDN, relaying AI requests through our proxy, mobile-app voice-memo transcription through Cloudflare Workers AI, and the anti-spam check on the public job request form (Cloudflare Turnstile) |
| Your browser's speech provider | Live voice transcription on supported web browsers, only when you choose it |
| PostHog | Product analytics tied to a random account ID, without client content |
| Sentry | Crash diagnostics so we can fix bugs |
| RevenueCat, with Apple & Google | Subscription processing and billing |
| Stripe | Processes deposit and invoice payments a customer makes on a shared pay page; we never receive full card or bank details |
| Resend | Account, team-invitation, and job-request notification email delivery |
| BigDataCloud | If you turn on photo location tagging: turning a photo's coordinates into a place name (reverse geocoding) |
| Anthropic (Claude) | Third-party AI: extracting job details from content you choose to analyze, and reading incoming job requests for businesses that have AI turned on (details below) |
| Intuit / QuickBooks | If you connect QuickBooks: adding customers you choose or finding an existing matching customer (details below) |
| Apple, Google | Sign in with Apple / Google (if you use it) and App Store / Google Play subscription billing |
Sharing with AI providers. Anthropic receives personal data when you choose an AI text or screenshot action, and when a job request comes in to a business that has AI turned on. Both happen only after that workspace has agreed to the in-app AI notice, and neither happens at all while AI is off. Under Anthropic's commercial terms, API customer content is not used to train its models. Anthropic's standard API retention policy says inputs and outputs may be retained for up to 30 days, subject to documented legal, safety, feedback, and customer-setting exceptions. In the mobile apps, Cloudflare receives voice audio only when you choose transcription. Cloudflare states in its Workers AI data policy that customer content is not used to train models without explicit consent. On supported web browsers, the browser vendor's own speech-service terms apply to live transcription. You can turn AI off in Settings → Setup & advanced → Privacy.
Connecting QuickBooks (Intuit). If you connect QuickBooks, the customer contact details you choose to send are shared with Intuit so Job Holster can create that customer or find an existing customer with the same display name. Job Holster does not update an existing customer, create invoices, or change your books. The connection starts only after you authorize it through Intuit's sign-in, and you can disconnect it at any time. Intuit processes the data under its own privacy policy.
We do not sell your data and we are not a data broker. We may disclose data if required by law or to protect rights and safety. The providers listed above process data on our behalf under contract, in the United States and other countries; where required, appropriate safeguards apply. You can request more detail about any provider at [email protected].
What we do not collect
- No device identifiers, no advertising identifier (IDFA), no contact lists, and no calendar entries. The only location we ever use is optional photo tagging, described above, and only if you turn it on.
- No access to your phone's SMS, iMessage, or call history. You paste in text yourself.
- No cross-app or cross-site tracking, and no advertising.
Access controls limit workspace data to signed-in members of that workspace. Teammates you invite can see shared jobs and records allowed by their role. People outside the workspace cannot access them through the app.
Cookies and local storage
The app uses your browser's localStorage to cache your data for offline access and to remember your sign-in session. It does not set tracking cookies. If you sign out and clear browser data, the local cache is removed.
Deleting your account
You can permanently delete your account from inside the app. Go to Settings → Setup & advanced, open Account settings, choose Delete my account, type the confirmation phrase, and confirm. If you are the only owner of a workspace with other members, the app requires you to remove those members or arrange a transfer first. A solely owned workspace without other members is deleted with its data. If you belong to someone else's shared workspace, your membership is removed, but shared records may remain available to that workspace. Account deletion clears the local cache on the device where you complete it; clear Job Holster data separately on any other device if needed. If you can no longer access the app, see our account-deletion page for an email-based request process. Aggregated, non-identifiable analytics events and security logs may persist for a limited time.
Data retention
We keep your account and content until you delete them. Soft-deleted rows are kept for 30 days before being permanently purged, so accidental deletions can be undone. Disaster-recovery backups taken by our cloud database provider are retained according to that provider's standard backup window and then deleted.
Approved estimates. An approval is kept as part of the business's record of that job, for as long as they keep the job, because it is the evidence the work was agreed to. If the business edits an estimate after it was approved, the version you approved and your approval of it are kept alongside the new one rather than overwritten, for the same reason. A business can turn a link off at any time, which stops it being viewable.
Job request forms. A request nobody has acted on yet keeps its photos for 60 days, and then the photos are deleted automatically. A request the business dismisses is kept for 30 days so they can undo that, and then it is deleted automatically. If the business adds the request to their jobs, what you sent becomes part of that job's records and is kept like the rest of their work until they delete it.
Security
Data is encrypted in transit using HTTPS/TLS. Access controls at the database layer restrict workspace data to authorized members. No system is perfectly secure, but we take reasonable measures to protect your information.
The spam check on job request forms. Because a request form is a public page that anyone with the link can open, it runs an automated check to tell a real person from a bot before it will accept a submission. That check is Cloudflare Turnstile, and running it sends your IP address, your browser's user-agent, and similar technical signals about your browser to Cloudflare, which processes them for us. It usually asks you to do nothing at all. It does not read what you typed into the form, and it is not used to profile you or to advertise to you. Cloudflare sets out what Turnstile collects and why in its Turnstile Privacy Addendum. This check runs on the web form only; the iPhone and Android apps do not use it.
Your rights and choices
- Delete your data: Settings → Setup & advanced → Account settings (see above).
- Sent a business a job request? You do not have an account to delete, so email [email protected] and tell us which business you contacted. We will remove what you sent from our systems. If they have already added it to their jobs, ask them directly as well, because at that point it is their record.
- Approved or declined an estimate? You do not have an account to delete, so email [email protected] and tell us which business sent it. We will remove what you sent from our systems. Because your approval is that business's record of an agreement, ask them directly as well.
- Turn off analytics: Settings → Setup & advanced → Privacy.
- Access, correct, and export: you can view and export your data in the app at any time; contact us for any additional request.
- Depending on where you live (for example, the EEA/UK under GDPR, or California under CCPA/CPRA), you may have additional rights. We do not sell or share your personal information for cross-context behavioral advertising. To exercise any right, email [email protected].
Children
Job Holster is a business tool and is not intended for anyone under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we will delete it. A business's job request form asks people to be 18 or older before sending a request, because asking for work on a property is a step towards a commercial arrangement.
Changes to this policy
We may update this policy. If it materially changes, we'll update the "Last updated" date above and surface a notice in the app on next sign-in.
Contact
Jobholster LLC, Missouri, United States. Privacy questions: [email protected]. General support: [email protected].
© 2026 Jobholster LLC. All rights reserved.